We are considering doing a Bro Workshop July 23-25 at UCSD in San Diego.
I would be highly interested in such a workshop too. My interest,
particularly, would be in advanced topics like:
Stateful matching when running in a cluster.
* Co-relating connections when running in a cluster.
* BRO RE engine internals and how to optimize it further?
* Providing more detailed statistics - like flow details and
analyzer/policy-module stats.
* Aggregating statistics when BRO is running in a clustered environment.
* Broccoli & interfacing BRO with other systems.
* Optimizing BRO in general.
We'll be able to make a decision as soon as someone can send us an agenda.
thanks
-vish